TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Fired employee deleted servers, causing it to lose S$918,000

56 点作者 bovem12 个月前

10 条评论

glonq12 个月前
&gt; His contract with NCS was terminated in October 2022 due to poor work performance and his official last date of employment was Nov 16, 2022<p>This is why you don&#x27;t force employees or contractors to work through their final two weeks. Too little benefit, too much risk.<p>&gt; After Kandula&#x27;s contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023.<p>Oh nevermind, it&#x27;s far worse than just that!
评论 #40662336 未加载
xyst12 个月前
Only $678K worth of damage? Rookie numbers.<p>Worked with a number of folks that caused much more than that just by mere accident. Not disgruntled or anything. Just “fat fingered” a command or had a momentary brain fart (deleted prod db instead of backup!).<p>Guy truly was incompetent and deserves everything coming to him.
评论 #40663511 未加载
rkwz12 个月前
&gt; On Mar 18 and 19, he ran a programmed script to delete 180 virtual servers in the system.<p>&gt; The system that Kandula’s former team was managing was used to test new software and programs before launch. In a statement to CNA on Wednesday, NCS said it was a &quot;standalone test system&quot;.<p>&gt; As a result of his actions, NCS suffered a loss of S$917,832.<p>Wondering if these are CI&#x2F;CD pipelines, and how the loss amount was calculated since these can be spun up again.
评论 #40662580 未加载
TacticalCoder12 个月前
There&#x27;s a reason why some companies are using measures that feel very inhuman when they fire someone: it&#x27;s because of people like the one from TFA.
评论 #40662207 未加载
评论 #40662270 未加载
评论 #40662393 未加载
评论 #40662518 未加载
评论 #40662481 未加载
评论 #40663341 未加载
评论 #40663910 未加载
technick12 个月前
The level of incompetence on NCS&#x27;s part is criminal, they absolutely deserved what they got. It could have been much worst, as in the malicious actor finding a way to insert code that makes it into production and then exfiltrating sensitive data to be sold on the dark web. Luckily Kandula wasn&#x27;t smart enough to think like one of us.<p>NCS sounds like a clown show based on this article. The administrator credentials should have been changed as soon as Kandula was let go. Ideally, these credentials shouldn&#x27;t have ever been used and everyone should be acting as themselves with a elevated privilege step.<p>As for the $678k in damages, why didn&#x27;t NCS have snapshots that they could have quickly restored? Sounds like their BCDR plans need to be reviewed and updated.<p>Moral of the story is don&#x27;t do business with NCS.
paulpauper12 个月前
<i>Kandula&#x27;s laptop was seized by the police and the script used to carry out the deletions was found on it.</i><p>full disk encryption is a thing. it&#x27;s amazing how people who are otherwise technically competent leave such obvious incrementing evidence on computer
评论 #40662052 未加载
评论 #40662454 未加载
评论 #40662098 未加载
评论 #40662509 未加载
评论 #40662066 未加载
评论 #40662501 未加载
评论 #40662434 未加载
评论 #40663542 未加载
评论 #40662060 未加载
InfiniteVortex12 个月前
I wonder how much he was fine (if he was - they also have caning as a penalty). Singapore is known to be incredibly strict with criminal punishments. There was a recent $8 billion money laundering case that garnered international headlines because SG is known to be corruption-free for the most part. I&#x27;m sure you can find the reasons for verdict (SG has no jury trials) and reasons for sentence. Generally, an incredibly well run state IMHO. (Yes, it has its downsides, criticisms and controversies). It&#x27;ll be interesting to see how PM Wong will govern compared to LKY &amp; LHL.
rekabis12 个月前
I’m sorry but based on this,<p>&gt; NCS is a company that offers information communication and technology services.<p>And more importantly, this:<p>&gt; After Kandula&#x27;s contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023.<p>The company is not just ignorant, but massively incompetent.<p>You don’t fire someone without totally withdrawing every last shred of access they have. The fact that he was able to use a common, generic administrative credential shows that NCS fails epically at even the simplest of security.
banku_brougham12 个月前
What about leaving an ssh key on there with a port open?
ssahoo11 个月前
180vms and 678k loss. So 3.5k a pop.